5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0033
PDF Viewer Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2023-26131
github.com/xyproto/algernon/engine Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-79 2 PoCs

All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.

CVE-2023-0537
Product Slider For WooCommerce Lite Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0360
Location Weather Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0166
Product Slider for WooCommerce by PickPlugins Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0167
GetResponse for WordPress Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0173
Drag & Drop Sales Funnel Builder for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-28666
InPost Gallery WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.

CVE-2023-0152
WP Multi Store Locator Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4811
WordPress File Upload Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.

CVE-2023-0995
unilogies/bumsys Web
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.

CVE-2023-42575
Samsung Pass General
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.

CVE-2023-30963
com.palantir.foundry:foundry-frontend Web
5.4
MEDIUM
EPSS
0.3%
2023 CWE-82 1 PoC

A security defect was discovered in Foundry Frontend which enabled users to perform Stored XSS attacks in Slate if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.229.0. The service was rolled out to all affected Foundry instances. No further intervention is required.

CVE-2023-42554
Samsung Pass General
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

CVE-2023-0081
MonsterInsights Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0168
Olevmedia Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0270
YaMaps for WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The YaMaps for WordPress Plugin WordPress plugin before 0.6.26 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-33829
Software Genérico Web Cloud
5.4
MEDIUM
EPSS
2.9%
2023 6 PoCs

A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field.

CVE-2023-0096
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0374
W4 Post List Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.